212-82 Exam Question 41

Thomas, an employee of an organization, is restricted to access specific websites from his office system. He is trying to obtain admin credentials to remove the restrictions. While waiting for an opportunity, he sniffed communication between the administrator and an application server to retrieve the admin credentials. Identify the type of attack performed by Thomas in the above scenario.
  • 212-82 Exam Question 42

    Cairo, an incident responder. was handling an incident observed in an organizational network. After performing all IH&R steps, Cairo initiated post-incident activities. He determined all types of losses caused by the incident by identifying And evaluating all affected devices, networks, applications, and software. Identify the post-incident activity performed by Cairo in this scenario.
  • 212-82 Exam Question 43

    Warren, a member of IH&R team at an organization, was tasked with handling a malware attack launched on one of servers connected to the organization's network. He immediately implemented appropriate measures to stop the infection from spreading to other organizational assets and to prevent further damage to the organization.
    Identify the IH&R step performed by Warren in the above scenario.
  • 212-82 Exam Question 44

    Nancy, a security specialist, was instructed to identify issues related to unexpected shutdown and restarts on a Linux machine. To identify the incident cause, Nancy navigated to a directory on the Linux system and accessed a log file to troubleshoot problems related to improper shutdowns and unplanned restarts.
    Identify the Linux log file accessed by Nancy in the above scenario.
  • 212-82 Exam Question 45

    The SOC department in a multinational organization has collected logs of a security event as
    "Windows.events.evtx". Study the Audit Failure logs in the event log file located in the Documents folder of the
    -Attacker Maehine-1" and determine the IP address of the attacker. (Note: The event ID of Audit failure logs is
    4625.)
    (Practical Question)